Abstract
Reliability and quality of service from information systems has been threatened by cyber intrusions. To protect information systems from intrusions and thus assure reliability and quality of service, it is highly desirable to develop techniques that detect intrusions. Many intrusions manifest in anomalous changes in intensity of events occurring in information systems. In this study, we apply, test, and compare two EWMA techniques to detect anomalous changes in event intensity for intrusion detection: EWMA for autocorrelated data and EWMA for uncorrelated data. Different parameter settings and their effects on performance of these EWMA techniques are also investigated to provide guidelines for practical use of these techniques.
Original language | English (US) |
---|---|
Pages (from-to) | 75-82 |
Number of pages | 8 |
Journal | IEEE Transactions on Reliability |
Volume | 52 |
Issue number | 1 |
DOIs | |
State | Published - Mar 2003 |
Keywords
- Anomaly detection
- Computer audit data
- Exponentially weighted moving average (EWMA)
- Information assurance
- Intrusion detection
ASJC Scopus subject areas
- Safety, Risk, Reliability and Quality
- Electrical and Electronic Engineering